about summary refs log tree commit diff
path: root/ops/secrets
diff options
context:
space:
mode:
authorVincent Ambo <mail@tazj.in>2021-12-10T13·11+0300
committerclbot <clbot@tvl.fyi>2021-12-10T19·31+0000
commit82a885a750cfe3bdf282a19a37f91842f374b24c (patch)
tree6a40e6f099a31bbffe386ddfbfa5ba621334df73 /ops/secrets
parentb1108821a9dbc617f02a4437c9300f5b0bdca479 (diff)
refactor(ops): Use besadii configuration from agenix r/3198
We already checked this in, but this commit adds the configuration for
making use of it.

There are two copies of besadii's JSON configuration with different
permissions.

Note that the buildkite-graphql-token path needs to be updated in
static-pipeline.yml, but this needs to happen in a separate commit
after deploy because the pipeline will break otherwise.

Change-Id: I6fab4bf1a2e679df7cf76521e2b53bd9dadbac62
Diffstat (limited to 'ops/secrets')
-rw-r--r--ops/secrets/buildkite-graphql-token.age9
-rw-r--r--ops/secrets/secrets.nix1
2 files changed, 10 insertions, 0 deletions
diff --git a/ops/secrets/buildkite-graphql-token.age b/ops/secrets/buildkite-graphql-token.age
new file mode 100644
index 000000000000..5a571f511c26
--- /dev/null
+++ b/ops/secrets/buildkite-graphql-token.age
@@ -0,0 +1,9 @@
+age-encryption.org/v1
+-> ssh-ed25519 dcsaLw xzwSc5FlU9NrAyQhMXigihf3oEE2yA8nZfpP3U1co1k
++nUTx+ppxHIgKs9RG0mhWG3a7OkbelZDNDiXabGIMrc
+-> ssh-ed25519 OkGqLg lTCF8xm2+wljZs6PyUeB6ySD9TEEAfQdbW3qIuat4gE
+THlu4VhAm5FKLYvc6ad6lFnlssVJsPiGqucSVF949vM
+-> 62T-grease 7 RH''g X
+4zRtTUAapv8
+--- d8zm0fuBJSw1oZmpsIAJ66YqkS3y/UBQzd/A2/8u17g
+i'`/햏(qciYfҜ"+s0X; 35΂ӄK?d%;v[
\ No newline at end of file
diff --git a/ops/secrets/secrets.nix b/ops/secrets/secrets.nix
index 66176c3b9ef3..9dae76d15ba5 100644
--- a/ops/secrets/secrets.nix
+++ b/ops/secrets/secrets.nix
@@ -14,6 +14,7 @@ let
 in {
   "besadii.age" = default;
   "buildkite-agent-token.age" = default;
+  "buildkite-graphql-token.age" = default;
   "clbot-ssh.age" = default;
   "clbot.age" = default;
   "gerrit-queue.age" = default;